diff --git a/backend/app/services/google_oauth.py b/backend/app/services/google_oauth.py index ab44336..d22cd05 100644 --- a/backend/app/services/google_oauth.py +++ b/backend/app/services/google_oauth.py @@ -1,6 +1,14 @@ import logging +import os from datetime import datetime, timezone +# Google frequently echoes back a scope string that's a superset/reordering +# of what we requested (e.g. we ask for "youtube", Google's token response +# also lists "youtube.readonly" since it's implied). oauthlib does an exact +# string comparison by default and raises on any mismatch -- this disables +# that overly strict check. Must be set before requests_oauthlib reads it. +os.environ.setdefault("OAUTHLIB_RELAX_TOKEN_SCOPE", "1") + import httpx from google.auth.transport.requests import Request as GoogleAuthRequest from google.oauth2.credentials import Credentials